Skip to content
COOEY

EXPOSURES › CVE-2025-55177

CVE-2025-55177

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-09-02 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-55177 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatchedrce

Meta WhatsApp allowed unauthorized triggering of URLs on users' devices.

Meta Platforms WhatsApp had an unpatched vulnerability that enabled an unrelated user to execute arbitrary URLs on a target's device, posing a significant security risk.

Shame score — Unpatched vulnerability allowing remote code execution.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Meta Platforms WhatsApp contains an incorrect authorization vulnerability due to an incomplete authorization of linked device synchronization messages. This vulnerability could allow an unrelated user to trigger processing of content from an arbitrary URL on a target’s device.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.